CVE-2015-8023
Ubuntu Security Notice USN-2811-1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The server implementation of the EAP-MSCHAPv2 protocol in the eap-mschapv2 plugin in strongSwan 4.2.12 through 5.x before 5.3.4 does not properly validate local state, which allows remote attackers to bypass authentication via an empty Success message in response to an initial Challenge message.
La implementación del servidor del protocolo EAP-MSCHAPv2 en el plugin eap-mschapv2 en strongSwan 4.2.12 hasta la versión 5.x en versiones anteriores a 5.3.4 no valida adecuadamente el estado local, lo que permite a atacantes remotos eludir la autenticación a través de un mensaje Success vacío en respuesta a un mensaje Challenge inicial.
It was discovered that the strongSwan eap-mschapv2 plugin incorrectly handled state. A remote attacker could use this issue to bypass authentication.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-10-29 CVE Reserved
- 2015-11-16 CVE Published
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/84947 | Vdb Entry | |
https://www.strongswan.org/blog/2015/11/16/strongswan-vulnerability-%28cve-2015-8023%29.html | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00025.html | 2023-11-07 | |
http://lists.opensuse.org/opensuse-updates/2015-11/msg00139.html | 2023-11-07 | |
http://www.debian.org/security/2015/dsa-3398 | 2023-11-07 | |
http://www.ubuntu.com/usn/USN-2811-1 | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 14.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "14.04" | lts |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 15.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "15.04" | - |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 15.10 Search vendor "Canonical" for product "Ubuntu Linux" and version "15.10" | - |
Affected
| ||||||
Strongswan Search vendor "Strongswan" | Strongswan Search vendor "Strongswan" for product "Strongswan" | 4.2.12 Search vendor "Strongswan" for product "Strongswan" and version "4.2.12" | - |
Affected
| ||||||
Strongswan Search vendor "Strongswan" | Strongswan Search vendor "Strongswan" for product "Strongswan" | 4.2.13 Search vendor "Strongswan" for product "Strongswan" and version "4.2.13" | - |
Affected
| ||||||
Strongswan Search vendor "Strongswan" | Strongswan Search vendor "Strongswan" for product "Strongswan" | 4.2.14 Search vendor "Strongswan" for product "Strongswan" and version "4.2.14" | - |
Affected
| ||||||
Strongswan Search vendor "Strongswan" | Strongswan Search vendor "Strongswan" for product "Strongswan" | 4.2.15 Search vendor "Strongswan" for product "Strongswan" and version "4.2.15" | - |
Affected
| ||||||
Strongswan Search vendor "Strongswan" | Strongswan Search vendor "Strongswan" for product "Strongswan" | 4.2.16 Search vendor "Strongswan" for product "Strongswan" and version "4.2.16" | - |
Affected
| ||||||
Strongswan Search vendor "Strongswan" | Strongswan Search vendor "Strongswan" for product "Strongswan" | 4.3.0 Search vendor "Strongswan" for product "Strongswan" and version "4.3.0" | - |
Affected
| ||||||
Strongswan Search vendor "Strongswan" | Strongswan Search vendor "Strongswan" for product "Strongswan" | 4.3.1 Search vendor "Strongswan" for product "Strongswan" and version "4.3.1" | - |
Affected
| ||||||
Strongswan Search vendor "Strongswan" | Strongswan Search vendor "Strongswan" for product "Strongswan" | 4.3.2 Search vendor "Strongswan" for product "Strongswan" and version "4.3.2" | - |
Affected
| ||||||
Strongswan Search vendor "Strongswan" | Strongswan Search vendor "Strongswan" for product "Strongswan" | 4.3.3 Search vendor "Strongswan" for product "Strongswan" and version "4.3.3" | - |
Affected
| ||||||
Strongswan Search vendor "Strongswan" | Strongswan Search vendor "Strongswan" for product "Strongswan" | 4.3.4 Search vendor "Strongswan" for product "Strongswan" and version "4.3.4" | - |
Affected
| ||||||
Strongswan Search vendor "Strongswan" | Strongswan Search vendor "Strongswan" for product "Strongswan" | 4.3.5 Search vendor "Strongswan" for product "Strongswan" and version "4.3.5" | - |
Affected
| ||||||
Strongswan Search vendor "Strongswan" | Strongswan Search vendor "Strongswan" for product "Strongswan" | 4.3.6 Search vendor "Strongswan" for product "Strongswan" and version "4.3.6" | - |
Affected
| ||||||
Strongswan Search vendor "Strongswan" | Strongswan Search vendor "Strongswan" for product "Strongswan" | 4.3.7 Search vendor "Strongswan" for product "Strongswan" and version "4.3.7" | - |
Affected
| ||||||
Strongswan Search vendor "Strongswan" | Strongswan Search vendor "Strongswan" for product "Strongswan" | 4.4.0 Search vendor "Strongswan" for product "Strongswan" and version "4.4.0" | - |
Affected
| ||||||
Strongswan Search vendor "Strongswan" | Strongswan Search vendor "Strongswan" for product "Strongswan" | 4.4.1 Search vendor "Strongswan" for product "Strongswan" and version "4.4.1" | - |
Affected
| ||||||
Strongswan Search vendor "Strongswan" | Strongswan Search vendor "Strongswan" for product "Strongswan" | 4.5.0 Search vendor "Strongswan" for product "Strongswan" and version "4.5.0" | - |
Affected
| ||||||
Strongswan Search vendor "Strongswan" | Strongswan Search vendor "Strongswan" for product "Strongswan" | 4.5.1 Search vendor "Strongswan" for product "Strongswan" and version "4.5.1" | - |
Affected
| ||||||
Strongswan Search vendor "Strongswan" | Strongswan Search vendor "Strongswan" for product "Strongswan" | 4.5.2 Search vendor "Strongswan" for product "Strongswan" and version "4.5.2" | - |
Affected
| ||||||
Strongswan Search vendor "Strongswan" | Strongswan Search vendor "Strongswan" for product "Strongswan" | 4.5.3 Search vendor "Strongswan" for product "Strongswan" and version "4.5.3" | - |
Affected
| ||||||
Strongswan Search vendor "Strongswan" | Strongswan Search vendor "Strongswan" for product "Strongswan" | 4.6.0 Search vendor "Strongswan" for product "Strongswan" and version "4.6.0" | - |
Affected
| ||||||
Strongswan Search vendor "Strongswan" | Strongswan Search vendor "Strongswan" for product "Strongswan" | 4.6.1 Search vendor "Strongswan" for product "Strongswan" and version "4.6.1" | - |
Affected
| ||||||
Strongswan Search vendor "Strongswan" | Strongswan Search vendor "Strongswan" for product "Strongswan" | 4.6.2 Search vendor "Strongswan" for product "Strongswan" and version "4.6.2" | - |
Affected
| ||||||
Strongswan Search vendor "Strongswan" | Strongswan Search vendor "Strongswan" for product "Strongswan" | 4.6.3 Search vendor "Strongswan" for product "Strongswan" and version "4.6.3" | - |
Affected
| ||||||
Strongswan Search vendor "Strongswan" | Strongswan Search vendor "Strongswan" for product "Strongswan" | 4.6.4 Search vendor "Strongswan" for product "Strongswan" and version "4.6.4" | - |
Affected
| ||||||
Strongswan Search vendor "Strongswan" | Strongswan Search vendor "Strongswan" for product "Strongswan" | 5.0.0 Search vendor "Strongswan" for product "Strongswan" and version "5.0.0" | - |
Affected
| ||||||
Strongswan Search vendor "Strongswan" | Strongswan Search vendor "Strongswan" for product "Strongswan" | 5.0.1 Search vendor "Strongswan" for product "Strongswan" and version "5.0.1" | - |
Affected
| ||||||
Strongswan Search vendor "Strongswan" | Strongswan Search vendor "Strongswan" for product "Strongswan" | 5.0.2 Search vendor "Strongswan" for product "Strongswan" and version "5.0.2" | - |
Affected
| ||||||
Strongswan Search vendor "Strongswan" | Strongswan Search vendor "Strongswan" for product "Strongswan" | 5.0.3 Search vendor "Strongswan" for product "Strongswan" and version "5.0.3" | - |
Affected
| ||||||
Strongswan Search vendor "Strongswan" | Strongswan Search vendor "Strongswan" for product "Strongswan" | 5.0.4 Search vendor "Strongswan" for product "Strongswan" and version "5.0.4" | - |
Affected
| ||||||
Strongswan Search vendor "Strongswan" | Strongswan Search vendor "Strongswan" for product "Strongswan" | 5.1.0 Search vendor "Strongswan" for product "Strongswan" and version "5.1.0" | - |
Affected
| ||||||
Strongswan Search vendor "Strongswan" | Strongswan Search vendor "Strongswan" for product "Strongswan" | 5.1.1 Search vendor "Strongswan" for product "Strongswan" and version "5.1.1" | - |
Affected
| ||||||
Strongswan Search vendor "Strongswan" | Strongswan Search vendor "Strongswan" for product "Strongswan" | 5.1.2 Search vendor "Strongswan" for product "Strongswan" and version "5.1.2" | - |
Affected
| ||||||
Strongswan Search vendor "Strongswan" | Strongswan Search vendor "Strongswan" for product "Strongswan" | 5.1.3 Search vendor "Strongswan" for product "Strongswan" and version "5.1.3" | - |
Affected
| ||||||
Strongswan Search vendor "Strongswan" | Strongswan Search vendor "Strongswan" for product "Strongswan" | 5.2.0 Search vendor "Strongswan" for product "Strongswan" and version "5.2.0" | - |
Affected
| ||||||
Strongswan Search vendor "Strongswan" | Strongswan Search vendor "Strongswan" for product "Strongswan" | 5.2.1 Search vendor "Strongswan" for product "Strongswan" and version "5.2.1" | - |
Affected
| ||||||
Strongswan Search vendor "Strongswan" | Strongswan Search vendor "Strongswan" for product "Strongswan" | 5.2.2 Search vendor "Strongswan" for product "Strongswan" and version "5.2.2" | - |
Affected
| ||||||
Strongswan Search vendor "Strongswan" | Strongswan Search vendor "Strongswan" for product "Strongswan" | 5.2.3 Search vendor "Strongswan" for product "Strongswan" and version "5.2.3" | - |
Affected
| ||||||
Strongswan Search vendor "Strongswan" | Strongswan Search vendor "Strongswan" for product "Strongswan" | 5.3.0 Search vendor "Strongswan" for product "Strongswan" and version "5.3.0" | - |
Affected
| ||||||
Strongswan Search vendor "Strongswan" | Strongswan Search vendor "Strongswan" for product "Strongswan" | 5.3.1 Search vendor "Strongswan" for product "Strongswan" and version "5.3.1" | - |
Affected
| ||||||
Strongswan Search vendor "Strongswan" | Strongswan Search vendor "Strongswan" for product "Strongswan" | 5.3.2 Search vendor "Strongswan" for product "Strongswan" and version "5.3.2" | - |
Affected
| ||||||
Strongswan Search vendor "Strongswan" | Strongswan Search vendor "Strongswan" for product "Strongswan" | 5.3.3 Search vendor "Strongswan" for product "Strongswan" and version "5.3.3" | - |
Affected
|